Tag: technology
-

The PI Earns His Keep: Tuning MDI, Taming False Positives, and Making Your Detection Stack Actually Livable
(Or: How to Stop the Noise Without Going Blind) Let’s set the scene. You’ve deployed MDI. The sensors are on every domain controller. It’s talking to Defender XDR. Sentinel is listening. Your Conditional Access policies are wired to respond to risk signals. Your playbooks are humming. You did the work, and you did it right.…
-

The PI Calls It In: Automated Response, Playbooks, and What Happens When Nobody’s Watching the Board
(Or: How to Make Sure Kevin Has a Very Bad Night Even When You’re Asleep) Kevin had a rough Post 2. He got flagged at reconnaissance. He got flagged at Kerberoasting. He got flagged at lateral movement. He got flagged at DCSync. The PI was on him the whole time, building the case file, correlating…
-

The PI Works a Case: What a Real Credential Attack Looks Like Through MDI’s Eyes
(Or, How Your Domain Controller Became the World’s Best Surveillance Camera (And Nobody Told the Attacker)) Last time, we introduced our grizzled PI properly. We talked about what he watches, how he thinks, where he fits in the ecosystem, and why hybrid environments need him in the basement whether they know it or not. Today,…
-

The Grizzled PI Gets His Close-Up: A Proper Introduction to Microsoft Defender for Identity
(Or, How Your On-Prem AD Has Been Lying to You (And He Already Knew)) We’ve built quite a cast of characters in this blog, haven’t we? We’ve got the bouncer at the front door – Conditional Access, checking credentials and deciding who gets past the velvet rope. We’ve got Security Camera Guy upstairs, watching the…
-

Security Copilot on the Case: What Happens When the New Hire Gets a Badge
Or: The Part Where Our Enthusiastic New Hire Actually Earns Their Keep Last time, we introduced Microsoft Copilot as the eager new hire who’s read every manual, means well, and just needs a little supervision before anything goes out the door. We talked about M365 Copilot making your inbox slightly less terrifying, and gave Security…
-

The Enthusiastic New Hire: A Field Guide to Microsoft Copilot
Or: How I Learned to Stop Worrying and Love the AI That cc:’s Everyone We’ve built quite a cast of characters in this world. The bouncer checking IDs at the door. The no-nonsense lady running the tool room. The guy in the chair watching the monitors. Everyone has a role. Everyone knows their lane. And…
-

Bending Logs Like Neo: Splunk, Sentinel, and the Event Hub Advantage
I’m a Microsoft fanboy – guilty as charged. With an E5 license, you get a treasure chest of security capabilities, and I’ll happily admit I lean hard into Redmond’s ecosystem. But here’s the thing: no platform is perfect. Not even Microsoft’s crown jewels. The future is built on taking the platform you have and making…
-

What Happens When the Bouncer Misses? Identifying Risky Behaviors in Azure
In our last blog post, we built out the walls, gave ourselves a nice lobby, and put the bouncer at the door. Everything is good to go and we’re safe now, right? HA! This is the internet we’re talking about, and try as we might, there’s always going to be a potential for Sneaky McSneakster…
